Joshua Rogers' Scribbles

Topics

Every post on this site, grouped by subject. If you’re new here, this is the fastest way to work out what this blog is about: pick whichever cluster looks interesting and go from there.

AI, LLMs, and AI slop (culture + security + tooling)

Critiques of LLM-generated code and culture, alongside hands-on evaluations of AI-powered security tooling: what these tools actually find, and the messes they leave behind.

Nginx, Gixy-Next, ReDoS, and regex security

Research into nginx configuration pitfalls — proxy_pass URL normalization, DNS caching, allow/deny surprises — plus Gixy-Next (the maintained fork of the Gixy configuration scanner) and work on detecting ReDoS-vulnerable regular expressions.

Web platform, browsers, feeds, and HTTP/TLS debugging

Debugging writeups from the web’s plumbing: HTTP/2 breakage in intercepting proxies, TLS session key extraction, sandboxed iframes, broken feed caching, and making Firefox behave.

FreeBSD, Macs, and hardened networking

Running FreeBSD on Apple hardware, locking down the network layer with encrypted DNS and NTP, and assorted macOS and desktop quality-of-life fixes.

Fuzzing and vulnerability research (AFL++, harnessing, corpora)

Practical fuzzing engineering with AFL++: harnessing interpreters and libraries, tuning campaigns, and the tricks that make large-scale fuzzing actually work.

SSH, LDAP, and internal-network offensive engineering

Offensive tooling and techniques for internal networks: SSH-Snake, SSH backdoors and quirks, LDAP monitoring, and post-exploitation adventures in Kubernetes and Vault.

Big writeups: incidents, vulns, audits, and DoS

The long ones: a 55-vulnerability Squid audit, supply-chain backdoors, libwebp fallout, and other incidents, audits, and denial-of-service research.

Auth, accounts, and credential abuse

How authentication breaks in practice: hardware keys and 2FA, session persistence, credential stuffing, and one very broken bank PIN.

Programming, tooling, and practical notes

Smaller tools and practical notes: bash oddities, decompiler abuse, crawlers, and development-environment setups that actually work.

Recon and scanning

Making nmap dramatically faster at service scanning, with measurements.

Video game history and culture series

Research into retro video game history around the world: regional markets, promotional bus tours, and cross-cultural essays.

Personal essays, travel, and culture series

Travel, immigration adventures, workplace culture, and the other things that don’t fit anywhere else.